*** tmhoang has quit IRC | 00:18 | |
*** tmhoang has joined #kata-general | 00:19 | |
kata-irc-bot1 | <gwenn.etourneau_kata-> Anyone ? | 01:15 |
---|---|---|
*** fuentess has quit IRC | 03:40 | |
kata-irc-bot1 | <eric.ernst> Kata just runs container images. | 03:45 |
kata-irc-bot1 | <eric.ernst> You mean you have something like a qcow or some other VM image you'd like to launch? | 03:45 |
kata-irc-bot1 | <eric.ernst> I think you'd want to use something like KubeVirt for that use case. | 03:45 |
kata-irc-bot1 | <eric.ernst> @gwenn.etourneau_kata- ^^ | 04:33 |
kata-irc-bot1 | <gwenn.etourneau_kata-> Thanks @eric.ernst, so Kata only use same isolation right ? | 04:34 |
kata-irc-bot1 | <eric.ernst> Correct. Really, the goal is for you to not worry about any kind of VM image, etc. Just focus on running your usual container workload, and we provide. the second layer of isolation. | 05:24 |
kata-irc-bot1 | <gwenn.etourneau_kata-> Got it. | 05:27 |
*** sgarzare has joined #kata-general | 08:21 | |
*** sameo has joined #kata-general | 08:28 | |
*** sameo has quit IRC | 10:29 | |
*** sameo has joined #kata-general | 10:35 | |
*** sameo has quit IRC | 10:46 | |
*** sameo has joined #kata-general | 11:11 | |
*** devimc has joined #kata-general | 12:53 | |
*** fuentess has joined #kata-general | 14:06 | |
*** devimc has quit IRC | 14:58 | |
*** devimc has joined #kata-general | 14:59 | |
*** sameo has quit IRC | 15:29 | |
*** sameo has joined #kata-general | 15:30 | |
*** sgarzare has quit IRC | 16:32 | |
kata-irc-bot1 | <anders.franzen> Hi Kata folks, I tried to run a kata-container pod i kubernetes. The was also an NSM client. NSM (Network Service Mesh) works by providing Unix sockets via the Device Plugin API in k8s. So when a client pod starts, it can communicate with the NSM control plane, using grpc over this unix socket. A service in NSM is delivered as an ethernet interface into the pod. NSM is using the Unix socket to do a setns, moving an interface | 18:18 |
kata-irc-bot1 | into the pod. Of course all this failed bad in with the client running as untrusted in kata. Now my question, how would I go about to enable the use of NSM in kata managed pods. I assume I would have to write som Agent that runs outside the VM??, I tried to search the messages here, but did not find anything about this, is it anything you have thought about? | 18:18 |
devimc | @anders.franzen 1.x or 2.x ? | 18:26 |
devimc | sidecar injection is not working in 2.x, well, at least not for me | 18:27 |
kata-irc-bot1 | <anders.franzen> Thanks for the answer, yes it was 2.0, would be possible for it to work with 1.x ?? | 18:32 |
devimc | @anders.franzen 1.x works for me | 18:33 |
devimc | 1.12.1 | 18:33 |
kata-irc-bot1 | <anders.franzen> Did you try Network Service Mesh? | 18:34 |
devimc | @anders.franzen, nop, just istio | 18:36 |
kata-irc-bot1 | <anders.franzen> Ok, but still usefull info Thank you! | 18:36 |
devimc | yw | 18:36 |
*** devimc has quit IRC | 21:57 | |
*** fuentess has quit IRC | 23:11 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!